Real-Time Analytics Platform

Architecture Views

21 views, in reading order. Every view ships three ways: an HTML page, an SVG that re-opens in diagrams.net fully editable, and draw.io source.

Twenty-one views of an Azure real-time analytics platform, ordered as one argument: what sits inside the boundary, what the parts are, where the data lives, what happens at runtime, how it is operated, and why it is safe. The load-bearing decision is that the durable event log and its immutable bronze capture are the system of record — every store downstream of them is rebuildable, which is what makes a 5-second freshness target survivable when something breaks.

Context and scope

The boundary: who produces events, who consumes analytics, and what the platform deliberately does not do.
01
Governance and platform
Governance and platform
Microsoft Entra ID
Microsoft Entra ID
Microsoft Purview
Microsoft Purview
Azure Monitor
Azure Monitor
Event producers
Event producers
Web & Mobile Apps
client SDK
Web & Mobile Apps...
Partner Systems
REST · OAuth2
Partner Systems...
Devices & Edge
MQTT / AMQP
Devices & Edge...
Operational Databases
Azure SQL · PostgreSQL
Operational Databases...
Existing Kafka Estate
Existing Kafka Estate
Reference Data Lake
ADLS Gen2
Reference Data Lake...
Analytics consumers
Analytics consumers
Business Analysts
Business Analysts
Operations & SRE
Operations & SRE
Downstream Applications
Downstream Applications
Alerting & Automation
Logic Apps
Alerting & Automation...
Real-Time Analytics Platform
Azure · event to insight < 5 s
Real-Time Analytics Platform...
Enterprise data estate
Enterprise data estate
Enterprise Warehouse
Microsoft Fabric
Enterprise Warehouse...
Data Science & ML
Azure Machine Learning
Data Science & ML...
HTTPS event batches
HTTPS event batches
server-side events
server-side events
telemetry
telemetry
CDC log stream
CDC log stream
mirrored topics
mirrored topics
reference dimensions
reference dimensions
live dashboards
live dashboards
operational views
operational views
gold event topics
gold event topics
threshold triggers
threshold triggers
OAuth2 · RBAC
OAuth2 · RBAC
catalogue · lineage
catalogue · lineage
telemetry · alerts
telemetry · alerts
historical export
historical export
feature extracts
feature extracts
Real-Time Analytics Platform — System Context
Real-Time Analytics Platform — System Context
Security / platform
Security / platform
External / third party
External / third party
Data store
Data store
Person or role
Person or role
event / async
event / async
batch
batch
synchronous
synchronous
two-way
two-way
v 1.0 · owner Data & AI Architecture · date 2026-08
v 1.0 · owner Data & AI Architecture · date 2026-08
Text is not SVG - cannot display
System Context Who produces events, who consumes analytics, and which enterprise systems the platform depends on — the boundary of scope with no internal components shown. HTML page SVG draw.io
02
Producers
Producers
Devices & Edge
MQTT / AMQP
Devices & Edge...
App & Web SDK
HTTPS batches
App & Web SDK...
OLTP & Kafka Sources
CDC · mirrored topics
OLTP & Kafka Sources...
Ingestion
Ingestion
API Management
Front Door · WAF · quota
API Management...
Event Collector
Container Apps
Event Collector...
Ingest Connectors
IoT Hub · Debezium
Ingest Connectors...
Durable event log
Durable event log
Schema Registry
Avro · BACKWARD
Schema Registry...
Azure Event Hubs
256 partitions · 7 d
Azure Event Hubs...
Event Hubs Capture
ADLS Gen2 bronze
Event Hubs Capture...
Stream processing
Stream processing
Dead-Letter Hub
14 d retention
Dead-Letter Hub...
Azure Databricks
Structured Streaming
Azure Databricks...
Window & Enrich
watermark 2 min
Window & Enrich...
Hot analytics store
Hot analytics store
Delta Lake
silver · gold
Delta Lake...
Azure Data Explorer
hot cache 31 d
Azure Data Explorer...
Materialized Views
1 min · 5 min · 1 h
Materialized Views...
Query and serving
Query and serving
Azure Cache for Redis
30 s TTL
Azure Cache for Redis...
Query API
Container Apps
Query API...
Dashboards
Power BI · Grafana
Dashboards...
Capture 15 min
Capture 15 min
poison events
poison events
replay
replay
pre-aggregated
pre-aggregated
High-Level Platform Architecture
High-Level Platform Architecture
External / third party
External / third party
Interface / broker
Interface / broker
Application we own
Application we own
Security / platform
Security / platform
Queue / topic
Queue / topic
Data store
Data store
batch
batch
failure / alternate
failure / alternate
synchronous
synchronous
Front Door, IoT Hub and the CDC connector are drawn individually in the container and integration views.
Front Door, IoT Hub and the CDC connector are drawn individually in the container and integration views.
v 1.0 · owner Data & AI Architecture · date 2026-08
v 1.0 · owner Data & AI Architecture · date 2026-08
Text is not SVG - cannot display
High-Level Architecture The end-to-end shape in one picture: managed ingestion into an Event Hubs durable log, Databricks stream processing, and Azure Data Explorer as the hot analytics store behind a governed query surface. HTML page SVG draw.io

Structure

The deployable parts, how they depend on each other, every interface, and where the tenant boundary sits.
03
Consumption
Consumption
Power BI
Power BI
Managed Grafana
Managed Grafana
Analytics Applications
Analytics Applications
Alerting & Automation
Alerting & Automation
Serving
Serving
Query API
REST over KQL
Query API...
KQL Functions
semantic layer
KQL Functions...
Result Cache
Azure Cache for Redis
Result Cache...
Gold Event Topics
Gold Event Topics
Analytics store
Analytics store
Azure Data Explorer
Azure Data Explorer
Materialized Views
Materialized Views
External Tables
ADLS Delta
External Tables...
Processing
Processing
Streaming Jobs
Azure Databricks
Streaming Jobs...
Enrichment & Joins
Enrichment & Joins
Windowed Aggregation
Windowed Aggregation
Replay & Backfill
Replay & Backfill
Event log
Event log
Azure Event Hubs
Azure Event Hubs
Schema Registry
Schema Registry
Bronze Capture
ADLS Gen2
Bronze Capture...
Dead-Letter Hub
Dead-Letter Hub
Ingestion
Ingestion
API Management
API Management
Event Collector
Event Collector
Azure IoT Hub
Azure IoT Hub
CDC Connectors
CDC Connectors
Platform services
Platform services
Microsoft Entra ID
Microsoft Entra ID
Azure Key Vault
Azure Key Vault
Azure Monitor
Azure Monitor
Microsoft Purview
Microsoft Purview
Azure DevOps
Terraform
Azure DevOps...
HTTPS
HTTPS
KQL
KQL
ingest sink
ingest sink
consume
consume
publish
publish
push
push
Layered Architecture
Layered Architecture
External / third party
External / third party
Interface / broker
Interface / broker
Application we own
Application we own
Data store
Data store
Queue / topic
Queue / topic
Security / platform
Security / platform
synchronous
synchronous
event / async
event / async
Dependencies point downward only. Gold topics are the one sanctioned shortcut past the serving layer.
Dependencies point downward only. Gold topics are the one sanctioned shortcut past the serving layer.
v 1.0 · owner Data & AI Architecture · date 2026-08
v 1.0 · owner Data & AI Architecture · date 2026-08
Text is not SVG - cannot display
Layered Architecture What depends on what. Dependencies point downward only; platform services are consumed by every layer above them. HTML page SVG draw.io
04
Azure Subscription · rta-prod
Azure Subscription · rta-prod
Ingestion spoke · snet-ingest
Ingestion spoke · snet-ingest
Azure Front Door
WAF · TLS 1.3
Azure Front Door...
API Management
Premium · per-tenant quota
API Management...
Event Collector
Container Apps · FastAPI
Event Collector...
Azure IoT Hub
per-device certificates
Azure IoT Hub...
CDC Connector
Debezium on ACA
CDC Connector...
Event backbone · snet-events
Event backbone · snet-events
Azure Event Hubs
Dedicated · 6 hubs
Azure Event Hubs...
Schema Registry
Avro · BACKWARD
Schema Registry...
Event Hubs Capture
Parquet · 15 min
Event Hubs Capture...
Dead-Letter Hub
14 d retention
Dead-Letter Hub...
Processing spoke · snet-compute
Processing spoke · snet-compute
Azure Databricks
VNet-injected · no public IP
Azure Databricks...
Streaming Jobs
1 s micro-batch
Streaming Jobs...
Checkpoint Store
ADLS Gen2 ZRS
Checkpoint Store...
Reference Delta Tables
broadcast joins
Reference Delta Tables...
Serving spoke · snet-serve
Serving spoke · snet-serve
Azure Data Explorer
leader · 12 nodes
Azure Data Explorer...
ADX Follower
read-only · BI
ADX Follower...
Query API
Container Apps · autoscale
Query API...
Azure Cache for Redis
Premium 26 GB
Azure Cache for Redis...
Power BI
Power BI
Managed Grafana
Managed Grafana
Microsoft Entra ID
Microsoft Entra ID
Azure Key Vault
Azure Key Vault
Azure Monitor
Azure Monitor
Microsoft Purview
Microsoft Purview
HTTPS
HTTPS
AMQP publish
AMQP publish
Kafka protocol
Kafka protocol
consumer group
consumer group
streaming ingest
streaming ingest
poison event
poison event
follower attach
follower attach
KQL
KQL
DirectQuery
DirectQuery
Container Architecture — Deployable Units
Container Architecture — Deployable Units
Security / platform
Security / platform
Interface / broker
Interface / broker
Application we own
Application we own
Queue / topic
Queue / topic
Data store
Data store
External / third party
External / third party
synchronous
synchronous
event / async
event / async
failure / alternate
failure / alternate
Every service reaches Event Hubs, ADLS and Key Vault over private endpoints; public network access is disabled.
Every service reaches Event Hubs, ADLS and Key Vault over private endpoints; public network access is disabled.
v 1.0 · owner Data & AI Architecture · date 2026-08
v 1.0 · owner Data & AI Architecture · date 2026-08
Text is not SVG - cannot display
Container Architecture The deployable units, the technology each runs on, and the protocol on every hop — what an engineering team actually builds and owns. HTML page SVG draw.io
05
Inbound producers
Inbound producers
Web & Mobile SDK
Web & Mobile SDK
Partner Services
Partner Services
Devices & Edge
Devices & Edge
Azure SQL Database
Azure SQL Database
Kafka Estate
Kafka Estate
Batch File Drops
Batch File Drops
Platform
Platform
API Management
every inbound interface
API Management...
Azure Event Hubs
durable event log
Azure Event Hubs...
Azure Data Explorer
hot analytics store
Azure Data Explorer...
Outbound consumers
Outbound consumers
Power BI
Power BI
Managed Grafana
Managed Grafana
Downstream Apps
Downstream Apps
Logic Apps
Logic Apps
Microsoft Fabric
Microsoft Fabric
Azure Machine Learning
Azure Machine Learning
HTTPS batch
HTTPS batch
REST · OAuth2
REST · OAuth2
MQTT · AMQP
MQTT · AMQP
CDC · Debezium
CDC · Debezium
MirrorMaker 2
MirrorMaker 2
SFTP to ADLS
SFTP to ADLS
DirectQuery
DirectQuery
ADX data source
ADX data source
gold topics
gold topics
threshold events
threshold events
continuous export
continuous export
Delta share
Delta share
Integration and Interface Catalogue
Integration and Interface Catalogue
External / third party
External / third party
Interface / broker
Interface / broker
Queue / topic
Queue / topic
Data store
Data store
event / async
event / async
synchronous
synchronous
batch
batch
Every inbound interface authenticates with Entra ID; no shared keys are issued to producers.
Every inbound interface authenticates with Entra ID; no shared keys are issued to producers.
v 1.0 · owner Integration Architecture · date 2026-08
v 1.0 · owner Integration Architecture · date 2026-08
Text is not SVG - cannot display
Integration and Interface Catalogue Every way the platform touches another system, with protocol, direction and cadence — the single page an enterprise architect can review against the estate. HTML page SVG draw.io
06
Azure Tenant · shared control plane
Azure Tenant · shared control plane
Identity and policy
Identity and policy
Microsoft Entra ID
app registration per tenant
Microsoft Entra ID...
Azure Policy
deny public endpoints
Azure Policy...
Azure Key Vault
CMK per tenant tier
Azure Key Vault...
Ingestion isolation
Ingestion isolation
Shared Namespace
partition key = tenant
Shared Namespace...
Dedicated Namespace
premium tenants
Dedicated Namespace...
APIM Quota Policy
RPS + burst per tenant
APIM Quota Policy...
Noisy Neighbour
shared-tier saturation
Noisy Neighbour...
Storage isolation
Storage isolation
ADX Database per Tier
shared · premium
ADX Database per Tier...
Row-Level Security
tenant_id predicate
Row-Level Security...
ADLS Container
one per tenant
ADLS Container...
Query isolation
Query isolation
Leader Cluster
ingest and write
Leader Cluster...
Follower · Dashboards
predictable latency
Follower · Dashboards...
Follower · Ad-hoc
exports and notebooks
Follower · Ad-hoc...
Workload Groups
concurrency caps
Workload Groups...
quota
quota
by tenant_id
by tenant_id
premium path
premium path
read replica
read replica
read replica
read replica
promotion path
promotion path
Tenancy and Workload Isolation
Tenancy and Workload Isolation
Security / platform
Security / platform
Queue / topic
Queue / topic
Interface / broker
Interface / broker
Risk / gap
Risk / gap
Data store
Data store
event / async
event / async
synchronous
synchronous
failure / alternate
failure / alternate
Shared tier is cost-optimised and rate-limited; premium tier buys its own namespace and follower.
Shared tier is cost-optimised and rate-limited; premium tier buys its own namespace and follower.
v 1.0 · owner Data & AI Architecture · date 2026-08
v 1.0 · owner Data & AI Architecture · date 2026-08
Text is not SVG - cannot display
Tenancy and Workload Isolation Where the tenant boundary sits at each layer, and how one tenant's traffic or one team's ad-hoc query is prevented from degrading everybody else. HTML page SVG draw.io

Data

What is stored, in which tier, for how long, under whose ownership, and how the event contract is governed.
07
Source
Source
Change Rows
Avro · row image
Change Rows...
Application Events
JSON · 1.1 KB avg
Application Events...
Device Telemetry
protobuf · 240 B
Device Telemetry...
Capture and validate
Capture and validate
Idempotency Key
event_id + payload hash
Idempotency Key...
Event Collector
schema validation
Event Collector...
Rejected Events
invalid schema
Rejected Events...
Durable log
Durable log
Bronze Capture
Parquet · 7 y · immutable
Bronze Capture...
Azure Event Hubs
7 d · 256 partitions
Azure Event Hubs...
Dead-Letter Hub
14 d
Dead-Letter Hub...
Process and enrich
Process and enrich
Dimension Join
broadcast Delta
Dimension Join...
Windowed Aggregation
tumbling · sliding · session
Windowed Aggregation...
Watermark Gate
lateness 2 min
Watermark Gate...
Hot store
Hot store
Silver & Gold Delta
ADLS · rebuildable
Silver & Gold Delta...
ADX Raw Table
31 d hot · 400 d total
ADX Raw Table...
Materialized Views
1 min · 5 min · 1 h
Materialized Views...
Serve
Serve
Gold Event Topics
enriched · async
Gold Event Topics...
Query API
SQL and KQL
Query API...
Dashboards
Power BI · Grafana
Dashboards...
schema fail
schema fail
Capture 15 min
Capture 15 min
unprocessable
unprocessable
replay
replay
sub-second reads
sub-second reads
Event Data Flow — Format, Cadence and Retention
Event Data Flow — Format, Cadence and Retention
External / third party
External / third party
Application we own
Application we own
Risk / gap
Risk / gap
Data store
Data store
Queue / topic
Queue / topic
Decision point
Decision point
Interface / broker
Interface / broker
failure / alternate
failure / alternate
batch
batch
synchronous
synchronous
Bronze is the only zone that cannot be rebuilt; everything downstream is derivable from it.
Bronze is the only zone that cannot be rebuilt; everything downstream is derivable from it.
v 1.0 · owner Data Architecture · date 2026-08
v 1.0 · owner Data Architecture · date 2026-08
Text is not SVG - cannot display
Event Data Flow Where data comes from, what format and cadence it moves in, what is retained at each hop, and where an event goes when it cannot be processed. HTML page SVG draw.io
08
Platform storage estate
Platform storage estate
Hot · Azure Data Explorer
Hot · Azure Data Explorer
Raw Event Table
hot cache 31 d
Raw Event Table...
Materialized Views
pre-aggregated metrics
Materialized Views...
Dimension Tables
reference lookups
Dimension Tables...
Late Arrival Table
beyond watermark
Late Arrival Table...
Warm · ADLS Gen2 Delta Lake
Warm · ADLS Gen2 Delta Lake
Bronze · Raw Capture
immutable · system of record
Bronze · Raw Capture...
Silver · Enriched
rebuildable from bronze
Silver · Enriched...
Gold · Curated Marts
rebuildable from silver
Gold · Curated Marts...
Cold · archive and export
Cold · archive and export
ADX Cold Tier
32 d to 400 d
ADX Cold Tier...
Blob Archive
7 y · legal hold
Blob Archive...
External Tables
hot + cold union query
External Tables...
Operational state
Operational state
Stream Checkpoints
ADLS · per job
Stream Checkpoints...
Schema Registry
versioned contracts
Schema Registry...
Offset & Watermark State
RocksDB + ADLS
Offset & Watermark State...
Single Unrebuildable Zone
bronze loss is terminal
Single Unrebuildable Zone...
Microsoft Purview
classification · lineage
Microsoft Purview...
Lifecycle Policy
hot to cool to archive
Lifecycle Policy...
Azure Key Vault
customer-managed keys
Azure Key Vault...
cache eviction
cache eviction
rebuild
rebuild
curate
curate
after 90 d
after 90 d
union query
union query
tier policy
tier policy
Storage Zones, Tiering and Retention
Storage Zones, Tiering and Retention
Data store
Data store
Security / platform
Security / platform
Risk / gap
Risk / gap
batch
batch
synchronous
synchronous
Retention is policy-driven per table; no data is deleted by a job, only by an expiry policy.
Retention is policy-driven per table; no data is deleted by a job, only by an expiry policy.
v 1.0 · owner Data Architecture · date 2026-08
v 1.0 · owner Data Architecture · date 2026-08
Text is not SVG - cannot display
Storage Zones, Tiering and Retention Every store the platform owns, grouped by who owns it and whether it can be rebuilt — the view that answers what happens if a given store is lost. HTML page SVG draw.io
10
Propose
Propose
Validate
Validate
Register
Register
Publish
Publish
Retire
Retire
Producer team
Producer team
Schema pull request
Schema pull request
Local compat check
Local compat check
SDK regenerated
SDK regenerated
Cut over to v(n)
Cut over to v(n)
Platform CI
Platform CI
Lint and policy
Azure DevOps
Lint and policy...
Backward-compat gate
Backward-compat gate
Push to registry
Push to registry
Contract tests
Contract tests
Sunset job
90 d window
Sunset job...
Schema Registry
Schema Registry
Diff against v(n-1)
Diff against v(n-1)
Avro schema v(n)
Avro schema v(n)
Schema ID in header
Schema ID in header
Marked deprecated
Marked deprecated
Consumers
Consumers
Impact report
Impact report
Consumer contract test
Consumer contract test
Resolve by schema ID
Resolve by schema ID
Migration confirmed
Migration confirmed
breaking change rejected
breaking change rejected
Schema Contract Governance
Schema Contract Governance
Application we own
Application we own
Decision point
Decision point
Security / platform
Security / platform
failure / alternate
failure / alternate
Only backward-compatible changes reach the registry; a breaking change requires a new event type.
Only backward-compatible changes reach the registry; a breaking change requires a new event type.
v 1.0 · owner Data Governance · date 2026-08
v 1.0 · owner Data Governance · date 2026-08
Text is not SVG - cannot display
Schema Contract Governance How an event schema changes without a redeployment and without breaking a consumer — the lane-by-lane path from proposal to retirement. HTML page SVG draw.io

Runtime

What actually happens per event: processing, windowing, the latency budget, the query path, and correction after the fact.
11
Read
Read
Checkpoint & Offsets
advanced after sink ack
Checkpoint & Offsets...
Event Hubs Source
maxOffsetsPerTrigger
Event Hubs Source...
Backpressure Control
trigger 1 s
Backpressure Control...
Decode
Decode
Undecodable Event
Undecodable Event
Avro Decode
Avro Decode
Schema Resolve
by schema ID
Schema Resolve...
Enrich
Enrich
Stateful Lookup
RocksDB state store
Stateful Lookup...
Broadcast Dimension Join
Delta reference
Broadcast Dimension Join...
Dimension Miss
late reference fallback
Dimension Miss...
Window
Window
Watermark 2 min
Watermark 2 min
Window Assignment
tumbling · sliding · session
Window Assignment...
Stateful Aggregation
per key and window
Stateful Aggregation...
Write
Write
Delta Silver Sink
txnAppId idempotence
Delta Silver Sink...
ADX Streaming Sink
ingest-by dedup tag
ADX Streaming Sink...
Dead-Letter Hub
quarantine · replayable
Dead-Letter Hub...
Signal
Signal
Gold Event Hub
enriched output
Gold Event Hub...
Checkpoint Commit
after sink ack
Checkpoint Commit...
Pipeline Metrics
lag · duration · rows
Pipeline Metrics...
decode failure
decode failure
beyond lateness
beyond lateness
Stream Processing Pipeline
Stream Processing Pipeline
Data store
Data store
Queue / topic
Queue / topic
Security / platform
Security / platform
Risk / gap
Risk / gap
Application we own
Application we own
Decision point
Decision point
failure / alternate
failure / alternate
Checkpoints commit only after every sink acknowledges, giving effectively-once delivery end to end.
Checkpoints commit only after every sink acknowledges, giving effectively-once delivery end to end.
v 1.0 · owner Streaming Engineering · date 2026-08
v 1.0 · owner Streaming Engineering · date 2026-08
Text is not SVG - cannot display
Stream Processing Pipeline What each micro-batch does, stage by stage, and exactly where the delivery guarantee is established. HTML page SVG draw.io
12
Window definition
Window definition
State kept
State kept
Emit trigger
Emit trigger
Late within 2 min
Late within 2 min
Beyond watermark
Beyond watermark
Tumbling · 1 min
Tumbling · 1 min
Fixed 60 s buckets
Fixed 60 s buckets
One aggregate per key
One aggregate per key
Watermark passes end
Watermark passes end
Updated in place
Updated in place
Routed to late table
Routed to late table
Sliding · 5 min / 1 min
Sliding · 5 min / 1 min
Five overlapping windows
Five overlapping windows
5x state per key
5x state per key
Every 1 min slide
Every 1 min slide
Overlaps recomputed
Overlaps recomputed
Dropped and counted
Dropped and counted
Session · 30 min gap
Session · 30 min gap
Gap-based boundary
Gap-based boundary
Open session state
Open session state
Inactivity timeout
Inactivity timeout
Session extended
Session extended
New session opened
New session opened
Out-of-order handling
Out-of-order handling
event_time not ingest_time
event_time not ingest_time
Per-partition watermark
Per-partition watermark
Min across partitions
Min across partitions
Reordered in window
Reordered in window
Backfill job corrects
Backfill job corrects
Windowing and Late-Arriving Events
Windowing and Late-Arriving Events
Application we own
Application we own
Data store
Data store
Decision point
Decision point
Queue / topic
Queue / topic
Risk / gap
Risk / gap
Security / platform
Security / platform
Watermark lateness is 2 minutes; a slow partition holds the global watermark and is alerted on.
Watermark lateness is 2 minutes; a slow partition holds the global watermark and is alerted on.
v 1.0 · owner Streaming Engineering · date 2026-08
v 1.0 · owner Streaming Engineering · date 2026-08
Text is not SVG - cannot display
Windowing and Late-Arriving Events Each window type against what state it keeps, when it emits, and what happens to an event that arrives after its window has closed. HTML page SVG draw.io
13
Producer SDK
Producer SDK
API Management
API Management
Event Collector
Event Collector
Azure Event Hubs
Azure Event Hubs
Databricks Stream
Databricks Stream
Azure Data Explorer
Azure Data Explorer
Dashboard
Dashboard
1. POST /v1/events · batch 500
1. POST /v1/events · batch 500
2. validate token, quota
2. validate token, quota
3. forward with tenant claim
3. forward with tenant claim
4. schema check, event_id
4. schema check, event_id
5. publish · key = tenant
5. publish · key = tenant
6. offset committed
6. offset committed
7. 202 Accepted · 200 ms
7. 202 Accepted · 200 ms
8. micro-batch · 1 s trigger
8. micro-batch · 1 s trigger
9. enrich, window, watermark
9. enrich, window, watermark
10. streaming ingest · dedup tag
10. streaming ingest · dedup tag
11. poison event to DLQ
11. poison event to DLQ
12. materialized view update
12. materialized view update
13. KQL over view
13. KQL over view
14. result · 350 ms p95
14. result · 350 ms p95
Event to Insight — Critical Path
Event to Insight — Critical Path
Budget: 200 ms accept, 1.5 s trigger, 1.2 s process, 1.5 s ingest visibility. 4.4 s of a 5 s p95 target.
Budget: 200 ms accept, 1.5 s trigger, 1.2 s process, 1.5 s ingest visibility. 4.4 s of a 5 s p95 target.
v 1.0 · owner Data & AI Architecture · date 2026-08
v 1.0 · owner Data & AI Architecture · date 2026-08
Text is not SVG - cannot display
Event to Insight — Critical Path One event from SDK call to dashboard pixel, with the latency budget spent at each hop against the 5-second p95 target. HTML page SVG draw.io
14
Serving tier
Serving tier
Client edge
Client edge
Azure Front Door
TLS · geo routing
Azure Front Door...
API Management
per-tenant RPS
API Management...
Query API
Container Apps · KEDA
Query API...
Acceleration
Acceleration
Azure Cache for Redis
55% hit · 30 s TTL
Azure Cache for Redis...
Materialized Views
1 min · 5 min · 1 h
Materialized Views...
KQL Functions
governed semantics
KQL Functions...
Azure Data Explorer
Azure Data Explorer
Leader Cluster
ingest and write
Leader Cluster...
Follower · Dashboards
read-only
Follower · Dashboards...
Follower · Ad-hoc
exports · notebooks
Follower · Ad-hoc...
Workload Groups
concurrency and memory caps
Workload Groups...
Consumption
Consumption
Power BI
DirectQuery
Power BI...
Managed Grafana
Managed Grafana
Gold Event Topics
Gold Event Topics
Notebooks & Ad-hoc
Notebooks & Ad-hoc
Microsoft Entra ID
on-behalf-of tokens
Microsoft Entra ID...
Microsoft Purview
column classification
Microsoft Purview...
TLS 1.3
TLS 1.3
HTTPS
HTTPS
cache lookup · 15 ms
cache lookup · 15 ms
miss · 350 ms
miss · 350 ms
resolved on follower
resolved on follower
attach
attach
attach
attach
DirectQuery KQL
DirectQuery KQL
ad-hoc KQL
ad-hoc KQL
Query and Serving Architecture
Query and Serving Architecture
Security / platform
Security / platform
Interface / broker
Interface / broker
Application we own
Application we own
Data store
Data store
External / third party
External / third party
Queue / topic
Queue / topic
synchronous
synchronous
Ad-hoc and export workloads never touch the cluster that serves dashboards.
Ad-hoc and export workloads never touch the cluster that serves dashboards.
v 1.0 · owner Data & AI Architecture · date 2026-08
v 1.0 · owner Data & AI Architecture · date 2026-08
Text is not SVG - cannot display
Query and Serving Architecture How a query reaches an answer in under 2 seconds while dashboards, ad-hoc analysis and exports run concurrently without competing. HTML page SVG draw.io
15
Trigger
Trigger
New Derived Metric
New Derived Metric
Incident or Defect
bad enrichment logic
Incident or Defect...
Change Approval
data owner sign-off
Change Approval...
Source of truth
Source of truth
Event Hubs Retention
last 7 d
Event Hubs Retention...
Bronze Capture
ADLS · 7 y
Bronze Capture...
Offset Range Selector
by event_time
Offset Range Selector...
Replay job
Replay job
Pinned Code Version
git SHA
Pinned Code Version...
Isolated Replay Job
separate Databricks pool
Isolated Replay Job...
Shadow Checkpoint
no production offsets
Shadow Checkpoint...
Shadow write
Shadow write
Delta Shadow Branch
Delta Shadow Branch
ADX Shadow Table
_replay suffix
ADX Shadow Table...
No Consumer Reads
shadow is invisible
No Consumer Reads...
Verify
Verify
Row and Metric Reconciliation
Row and Metric Reconciliation
Variance Gate
below 0.1%
Variance Gate...
Discard and Re-run
Discard and Re-run
Cut over
Cut over
Materialized View Rebuild
Materialized View Rebuild
Atomic Table Swap
rename in ADX
Atomic Table Swap...
Consumer Notice
restated window
Consumer Notice...
variance high
variance high
re-run
re-run
Replay, Backfill and Correction
Replay, Backfill and Correction
Application we own
Application we own
Risk / gap
Risk / gap
Decision point
Decision point
Queue / topic
Queue / topic
Data store
Data store
Security / platform
Security / platform
failure / alternate
failure / alternate
Production consumers never read a shadow table; the swap is the only moment they see a change.
Production consumers never read a shadow table; the swap is the only moment they see a change.
v 1.0 · owner Platform Operations · date 2026-08
v 1.0 · owner Platform Operations · date 2026-08
Text is not SVG - cannot display
Replay, Backfill and Correction How a defect discovered after the fact is corrected without taking the platform down or letting a consumer read a half-corrected table. HTML page SVG draw.io

Operations

Where it runs, how a change reaches production, how it is watched, and how it recovers.
16
Azure · Sweden Central (primary)
Azure · Sweden Central (primary)
Hub VNet · shared services
Hub VNet · shared services
Azure Firewall
egress control
Azure Firewall...
Private DNS Zones
privatelink.*
Private DNS Zones...
Azure Bastion
no public RDP/SSH
Azure Bastion...
ExpressRoute Gateway
on-premises CDC
ExpressRoute Gateway...
Zone-redundant compute and messaging
Zone-redundant compute and messaging
Availability Zone 1
Availability Zone 1
Event Hubs CU
Event Hubs CU
Databricks Workers
Databricks Workers
ADX Nodes x4
ADX Nodes x4
Availability Zone 2
Availability Zone 2
Event Hubs CU
Event Hubs CU
Databricks Workers
Databricks Workers
ADX Nodes x4
ADX Nodes x4
Availability Zone 3
Availability Zone 3
Event Hubs CU
Event Hubs CU
Databricks Workers
Databricks Workers
ADX Nodes x4
ADX Nodes x4
Zone-redundant state
Zone-redundant state
ADLS Gen2
ZRS · hierarchical
ADLS Gen2...
Checkpoint Container
per streaming job
Checkpoint Container...
Azure Key Vault
HSM · CMK
Azure Key Vault...
Azure Cache for Redis
zone-redundant premium
Azure Cache for Redis...
Azure · Germany West Central (DR)
Azure · Germany West Central (DR)
Warm standby
Warm standby
Event Hubs Geo-DR Alias
metadata replication
Event Hubs Geo-DR Alias...
ADX Follower Cluster
read-only standby
ADX Follower Cluster...
ADLS GRS Replica
bronze archive
ADLS GRS Replica...
Terraform Standby Stack
apply on declare
Terraform Standby Stack...
Azure Monitor
cross-region workspace
Azure Monitor...
Microsoft Entra ID
global
Microsoft Entra ID...
Azure DevOps
self-hosted agents
Azure DevOps...
geo-DR pair
geo-DR pair
GRS replication
GRS replication
attach
attach
Deployment and Infrastructure
Deployment and Infrastructure
Security / platform
Security / platform
Interface / broker
Interface / broker
Queue / topic
Queue / topic
Application we own
Application we own
Data store
Data store
event / async
event / async
batch
batch
RTO 60 min, RPO 5 min. DR is warm: capacity is provisioned on declare, not held idle.
RTO 60 min, RPO 5 min. DR is warm: capacity is provisioned on declare, not held idle.
v 1.0 · owner Cloud Platform · date 2026-08
v 1.0 · owner Cloud Platform · date 2026-08
Text is not SVG - cannot display
Deployment and Infrastructure What runs where, which failure domains it spans, and what is actually standing by in the secondary region. HTML page SVG draw.io
17
Source
Source
Terraform Modules
infrastructure as code
Terraform Modules...
Azure Repos
trunk + short branches
Azure Repos...
Schema Contracts
versioned Avro
Schema Contracts...
Build and test
Build and test
Unit & PySpark Tests
Unit & PySpark Tests
Schema Compat Gate
Schema Compat Gate
SAST & IaC Scan
Defender for DevOps
SAST & IaC Scan...
Dev
Dev
Ephemeral ADX Database
torn down nightly
Ephemeral ADX Database...
Dev Stream Job
feature branch
Dev Stream Job...
Synthetic Event Generator
replayed production shape
Synthetic Event Generator...
Test and UAT
Test and UAT
Shadow Traffic
5% mirrored
Shadow Traffic...
Latency Gate
5 s p95 end to end
Latency Gate...
Consumer Contract Tests
Consumer Contract Tests
Production
Production
Change Approval
Change Approval
Blue/Green Stream Job
new consumer group
Blue/Green Stream Job...
View Rebuild Guard
no read downtime
View Rebuild Guard...
Post-release
Post-release
Error Budget Update
Error Budget Update
48 h Watch
lag and freshness
48 h Watch...
Auto Rollback
on lag breach
Auto Rollback...
breaking
breaking
revert
revert
CI/CD and Environment Promotion
CI/CD and Environment Promotion
Security / platform
Security / platform
Application we own
Application we own
Decision point
Decision point
Data store
Data store
failure / alternate
failure / alternate
Blue/green uses a second consumer group replaying from the same offsets, so no event is skipped at cut-over.
Blue/green uses a second consumer group replaying from the same offsets, so no event is skipped at cut-over.
v 1.0 · owner Platform Engineering · date 2026-08
v 1.0 · owner Platform Engineering · date 2026-08
Text is not SVG - cannot display
CI/CD and Environment Promotion How a change reaches production, what stops a bad one at each gate, and how a streaming job is released without skipping an event. HTML page SVG draw.io
18
Ingestion
Ingestion
Event log
Event log
Processing
Processing
Hot store
Hot store
Serving
Serving
Latency and lag
Latency and lag
Accept p95 · 200 ms
Accept p95 · 200 ms
Consumer lag
Consumer lag
Batch duration
Batch duration
Ingestion latency
Ingestion latency
Query p95 · 2 s
Query p95 · 2 s
Throughput
Throughput
Events accepted/s
Events accepted/s
Throughput units
Throughput units
Rows per batch
Rows per batch
Rows ingested/min
Rows ingested/min
Concurrent queries
Concurrent queries
Errors
Errors
4xx / 5xx rate
4xx / 5xx rate
Quota throttles
Quota throttles
Failed batches
Failed batches
Ingestion failures
Ingestion failures
Query timeouts
Query timeouts
Data quality
Data quality
Schema rejects
Schema rejects
Dead-letter depth
Dead-letter depth
Late and dropped events
Late and dropped events
Count reconciliation
Count reconciliation
Freshness watermark
Freshness watermark
Alerting
Alerting
Accept-rate burn alert
Accept-rate burn alert
Lag over 60 s pages
Lag over 60 s pages
Checkpoint stall pages
Checkpoint stall pages
Freshness SLO burn
Freshness SLO burn
Query SLO burn
Query SLO burn
Observability and Service Level Objectives
Observability and Service Level Objectives
Security / platform
Security / platform
Risk / gap
Risk / gap
Application we own
Application we own
Queue / topic
Queue / topic
Every event carries event_id and trace context, so a single record is traceable from SDK to dashboard.
Every event carries event_id and trace context, so a single record is traceable from SDK to dashboard.
v 1.0 · owner SRE · date 2026-08
v 1.0 · owner SRE · date 2026-08
Text is not SVG - cannot display
Observability and Service Level Objectives Which signal is collected at which stage, and which of them will page somebody — the matrix an SRE reads before accepting the service. HTML page SVG draw.io

Assurance

Trust boundaries, what crosses them, and how producers and consumers prove who they are.
20
Untrusted · internet
Untrusted · internet
Producer Applications
Producer Applications
Partner Systems
Partner Systems
Forged Event Injection
stolen client secret
Forged Event Injection...
Perimeter · edge services
Perimeter · edge services
Azure Front Door
WAF · DDoS · TLS 1.3
Azure Front Door...
API Management
OAuth2 · quota · mTLS
API Management...
Azure IoT Hub
per-device X.509
Azure IoT Hub...
Private · ingestion and processing
Private · ingestion and processing
Event Collector
managed identity
Event Collector...
Azure Event Hubs
private endpoint only
Azure Event Hubs...
Azure Databricks
VNet-injected · no public IP
Azure Databricks...
Microsoft Entra ID
workload identity federation
Microsoft Entra ID...
Restricted · data and keys
Restricted · data and keys
Azure Data Explorer
CMK · row-level security
Azure Data Explorer...
ADLS Gen2
CMK · immutable bronze
ADLS Gen2...
Azure Key Vault
HSM · 12-month rotation
Azure Key Vault...
Audit Log
write-once · 7 y
Audit Log...
HTTPS 443
HTTPS 443
OAuth2 tokens
OAuth2 tokens
claim mismatch
claim mismatch
WAF-filtered
WAF-filtered
private link · mTLS
private link · mTLS
routing endpoint
routing endpoint
AMQP publish
AMQP publish
consumer group
consumer group
ingest
ingest
checkpoints
checkpoints
key access
key access
audit trail
audit trail
Security Architecture — Trust Zones
Security Architecture — Trust Zones
External / third party
External / third party
Risk / gap
Risk / gap
Security / platform
Security / platform
Interface / broker
Interface / broker
Application we own
Application we own
Queue / topic
Queue / topic
Data store
Data store
synchronous
synchronous
failure / alternate
failure / alternate
event / async
event / async
No component holds a shared key. Every service-to-service hop uses a managed identity over a private endpoint.
No component holds a shared key. Every service-to-service hop uses a managed identity over a private endpoint.
v 1.0 · owner Security Architecture · date 2026-08
v 1.0 · owner Security Architecture · date 2026-08
Text is not SVG - cannot display
Security Architecture — Trust Zones Where the trust boundaries are, what crosses each one and under what authentication, and where an attacker with a stolen credential actually arrives. HTML page SVG draw.io
Open svg/<view>.svg or drawio/<view>.drawio in draw.io Desktop or at app.diagrams.net to edit. The SVG carries the diagram inside it, so it is both the picture and the source. This folder is self-contained — copy it whole and every link still resolves.